HEX

Warning: set_time_limit() [function.set-time-limit]: Cannot set time limit - prohibited by configuration in /home/u547966/brikov.ru/www/wp-content/plugins/admin-menu-editor/menu-editor.php on line 745
Server: Apache
System: Linux 4.19.0-0.bpo.9-amd64 x86_64 at red40
User: u547966 (5490)
PHP: 5.3.29-mh2
Disabled: syslog, dl, popen, proc_open, proc_nice, proc_get_status, proc_close, proc_terminate, posix_mkfifo, chown, chgrp, accelerator_reset, opcache_reset, accelerator_get_status, opcache_get_status, pcntl_alarm, pcntl_fork, pcntl_waitpid, pcntl_wait, pcntl_wifexited, pcntl_wifstopped, pcntl_wifsignaled, pcntl_wifcontinued, pcntl_wexitstatus, pcntl_wtermsig, pcntl_wstopsig, pcntl_signal, pcntl_signal_dispatch, pcntl_get_last_error, pcntl_strerror, pcntl_sigprocmask, pcntl_sigwaitinfo, pcntl_sigtimedwait, pcntl_exec, pcntl_getpriority, pcntl_setpriority
Upload Files
File: //usr/share/auditbeat/kibana/7/search/e8734160-c24c-11e7-8692-232bd1143e8a-ecs.json
{
    "attributes": {
        "columns": [
            "agent.name",
            "auditd.summary.how",
            "auditd.summary.object.primary",
            "auditd.summary.object.secondary",
            "auditd.data.socket.family",
            "event.action"
        ],
        "description": "",
        "hits": 0,
        "kibanaSavedObjectMeta": {
            "searchSourceJSON": {
                "filter": [
                    {
                        "$state": {
                            "store": "appState"
                        },
                        "meta": {
                            "alias": null,
                            "disabled": false,
                            "indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index",
                            "key": "event.module",
                            "negate": false,
                            "params": {
                                "query": "auditd",
                                "type": "phrase"
                            },
                            "type": "phrase",
                            "value": "auditd"
                        },
                        "query": {
                            "match": {
                                "event.module": {
                                    "query": "auditd",
                                    "type": "phrase"
                                }
                            }
                        }
                    },
                    {
                        "$state": {
                            "store": "appState"
                        },
                        "meta": {
                            "alias": null,
                            "disabled": false,
                            "indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.filter[1].meta.index",
                            "key": "auditd.summary.object.type",
                            "negate": false,
                            "params": {
                                "query": "socket",
                                "type": "phrase"
                            },
                            "type": "phrase",
                            "value": "socket"
                        },
                        "query": {
                            "match": {
                                "auditd.summary.object.type": {
                                    "query": "socket",
                                    "type": "phrase"
                                }
                            }
                        }
                    },
                    {
                        "$state": {
                            "store": "appState"
                        },
                        "exists": {
                            "field": "auditd.summary.object.primary"
                        },
                        "meta": {
                            "alias": null,
                            "disabled": false,
                            "indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.filter[2].meta.index",
                            "key": "auditd.summary.object.primary",
                            "negate": false,
                            "type": "exists",
                            "value": "exists"
                        }
                    },
                    {
                        "$state": {
                            "store": "appState"
                        },
                        "meta": {
                            "alias": null,
                            "disabled": false,
                            "indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.filter[3].meta.index",
                            "key": "query",
                            "negate": false,
                            "type": "custom",
                            "value": "{\"terms\":{\"auditd.data.syscall\":[\"accept\",\"accept4\",\"recvfrom\",\"recvmsg\"]}}"
                        },
                        "query": {
                            "terms": {
                                "auditd.data.syscall": [
                                    "accept",
                                    "accept4",
                                    "recvfrom",
                                    "recvmsg"
                                ]
                            }
                        }
                    }
                ],
                "highlightAll": true,
                "indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.index",
                "query": {
                    "language": "kuery",
                    "query": ""
                },
                "version": true
            }
        },
        "sort": [
            [
                "@timestamp",
                "desc"
            ]
        ],
        "title": "Socket Accept / Recvfrom [Auditbeat Auditd] ECS",
        "version": 1
    },
    "coreMigrationVersion": "8.0.0",
    "id": "e8734160-c24c-11e7-8692-232bd1143e8a-ecs",
    "migrationVersion": {
        "search": "7.9.3"
    },
    "references": [
        {
            "id": "auditbeat-*",
            "name": "kibanaSavedObjectMeta.searchSourceJSON.index",
            "type": "index-pattern"
        },
        {
            "id": "auditbeat-*",
            "name": "kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index",
            "type": "index-pattern"
        },
        {
            "id": "auditbeat-*",
            "name": "kibanaSavedObjectMeta.searchSourceJSON.filter[1].meta.index",
            "type": "index-pattern"
        },
        {
            "id": "auditbeat-*",
            "name": "kibanaSavedObjectMeta.searchSourceJSON.filter[2].meta.index",
            "type": "index-pattern"
        },
        {
            "id": "auditbeat-*",
            "name": "kibanaSavedObjectMeta.searchSourceJSON.filter[3].meta.index",
            "type": "index-pattern"
        }
    ],
    "type": "search",
    "updated_at": "2021-08-04T16:35:59.895Z",
    "version": "WzQ5ODIsMV0="
}